CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
4,085 results Clear all
CVE-2008-6816 EPSS 0.11
Eaton Network Shutdown Module < 3.1_beta - Authentication Bypass
Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec_action.php.
CWE-287 May 28, 2009
CVE-2008-6815 1 PoC Analysis EPSS 0.04
Myktools - Authentication Bypass
mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.
CWE-287 May 28, 2009
CVE-2009-1754 EPSS 0.00
Google Android - Authentication Bypass
The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package that specifies a shared user ID with an arbitrary application.
CWE-287 May 26, 2009
CVE-2009-1670 1 PoC Analysis EPSS 0.03
Tcpdb - Authentication Bypass
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information.
CWE-287 May 18, 2009
CVE-2009-1664 1 PoC Analysis EPSS 0.03
Easy-scripts Answer And Question Script - Authentication Bypass
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.
CWE-287 May 18, 2009
CVE-2009-1638 1 PoC Analysis EPSS 0.02
T-dreams Job Career Package - Authentication Bypass
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.
CWE-287 May 15, 2009
CVE-2009-1629 EPSS 0.01
Antony Lesuisse Ajaxterm < 0.10 - Authentication Bypass
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.
CWE-287 May 14, 2009
CVE-2009-1580 EPSS 0.01
Squirrelmail < 1.4.17 - Authentication Bypass
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.
CWE-287 May 14, 2009
CVE-2009-1619 1 PoC Analysis EPSS 0.02
Teraway Filestream - Authentication Bypass
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
CWE-287 May 12, 2009
CVE-2009-1618 1 PoC Analysis EPSS 0.02
Teraway Livehelp - Authentication Bypass
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.
CWE-287 May 12, 2009
CVE-2009-1617 1 PoC Analysis EPSS 0.02
Teraway Linktracker - Authentication Bypass
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&lvl=1 value for the twLTadmin cookie.
CWE-287 May 12, 2009
CVE-2008-6804 1 PoC Analysis EPSS 0.02
Tribiq Cms - Authentication Bypass
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue
CWE-287 May 11, 2009
CVE-2009-1596 6.5 MEDIUM EPSS 0.00
Igniterealtime Openfire < 3.6.5 - Authentication Bypass
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
CWE-287 May 11, 2009
CVE-2009-1595 1 PoC Analysis EPSS 0.08
Igniterealtime Openfire < 3.6.3 - Authentication Bypass
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
CWE-287 May 11, 2009
CVE-2009-1587 1 PoC Analysis EPSS 0.02
Kalptarudemos Php Site Lock - Authentication Bypass
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.
CWE-287 May 07, 2009
CVE-2009-1549 1 PoC Analysis EPSS 0.03
Agtc Myshop - Authentication Bypass
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."
CWE-287 May 06, 2009
CVE-2009-1504 1 PoC Analysis EPSS 0.00
Xigla Absolute Control Panel XE - Authentication Bypass
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."
CWE-287 May 01, 2009
CVE-2009-1489 1 PoC Analysis EPSS 0.02
Rens Rikkerink Fungamez - Authentication Bypass
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.
CWE-287 Apr 29, 2009
CVE-2008-6763 1 PoC Analysis EPSS 0.02
Hypersilence Silentum Loginsys - Authentication Bypass
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.
CWE-287 Apr 28, 2009
CVE-2009-0662 EPSS 0.00
PlonePAS <3.9-<3.2.2 - Info Disclosure
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
CWE-287 Apr 23, 2009